# Portfolio Governance Report

_HumanOSE — AI governance across the enterprise portfolio: visible, controllable, exportable, verifiable. No legal compliance certification._

**Product:** HumanOSE  
**Scope:** All registered AI use cases (synthetic)  
**Language:** EN  
**Data mode:** synthetic  
**Generated at:** 2026-09-04T06:32:26.799Z  
**Total AI use cases:** 12  
**Integrity hash:** 21d85bc8e2009d34…  

> Portfolio view based on synthetic / staging data. No real personal, tenant or employee data.

> This portfolio report does not certify legal compliance.

## Executive Overview

- **Total AI use cases:** 12
- **Systems:** 7
- **Governance Readiness:** 3/12 presentable (reviewed + anchored)
- **Evidence coverage:** 769 Evidence events · invalid (suspected tampering)
- **Human oversight (portfolio):** 3/12 with an accountable human
- **Open owner decisions:** 9
- **Open near high-risk items:** 1

## System coverage

| Source system | Total AI use cases | Highest risk class | Open controls | Reviewed controls | Number of evidence events |
|---|---|---|---|---|---|
| causax | 6 | Near high-risk — mandatory human oversight, external legal review recommended | 30 | 1 | 184 |
| dialekt-x | 1 | Limited risk — review transparency obligations | 1 | 0 | 33 |
| humanx-ois | 1 | Near high-risk — mandatory human oversight, external legal review recommended | 15 | 0 | 34 |
| spacemytime | 1 | Limited risk — review transparency obligations | 1 | 0 | 23 |
| decision-trust | 1 | Minimal risk — baseline documentation | 0 | 0 | 27 |
| miios-x | 1 | Limited risk — review transparency obligations | 1 | 0 | 31 |
| seos | 1 | Minimal risk — baseline documentation | 0 | 0 | 30 |

## Risk distribution (preliminary)

> Preliminary governance classification only — does not replace a conclusive legal assessment.

| Risk class | Count |
|---|---|
| Suspected prohibited practice — immediate human and legal review required | 0 |
| Near high-risk — mandatory human oversight, external legal review recommended | 2 |
| Elevated risk — human review required | 2 |
| Limited risk — review transparency obligations | 4 |
| Minimal risk — baseline documentation | 2 |
| Not classified | 2 |

## Policy control coverage

- **Total applicable controls:** 55
- **Reviewed (evidence):** 1
- **Evidence attached:** 6
- **Open:** 48
- **Not applicable:** 0
- **Blocked controls (near high-risk, gate-dependent):** 29
- **Controls with pending human review:** 46

## Evidence coverage

- **Evidence events:** 769
- **Evidence chain status:** invalid (suspected tampering)
- **Generated report exports:** 284
- **Last evidence timestamp:** 2026-09-04T06:31:09.483Z

> Simulated anchoring (PageCipher integration pending) — marked as a simulation.

### PageCipher anchor coverage

- **PageCipher integration status:** Active (HTTP integration with PageCipher)
- **Anchored evidence events:** 296
- **Pending anchors:** 0
- **Failed anchors:** 0
- **Verified:** 0

> The PageCipher anchor proves the integrity and provenance of the evidence — it does not certify legal compliance.

## Human oversight (portfolio)

- **with an accountable human:** 3
- **without an assigned reviewer:** 7
- **with final human approval:** 3
- **blocked until legal review/Owner GO:** 1

> Human responsibility remains mandatory; AI does not make automatic decisions about persons.

## Open owner decisions

- External legal review required — 2 (uc\_cx\_a01, uc\_humanx\_skillmatch)
- Owner approval (GO) required — 2 (uc\_cx\_a01, uc\_humanx\_skillmatch)
- GO-DATA required (processing of real personal data not approved) — 3 (uc\_cx\_a01, uc\_cx\_c03, uc\_humanx\_skillmatch)
- GO-PAGECIPHER required (real evidence anchoring instead of simulation) — 1
- Penetration test required before productive go-live — 1

## Board summary

- Strong: Governance is documented per use case — with hash-chained evidence and human oversight for near high-risk cases.
- Open: Near high-risk use cases require external legal review and owner approval; PageCipher real anchoring and GO-DATA are pending.
- Presentable: Use cases with human approval and anchored evidence are demonstrable; the Governance Report is client-ready.
- Not yet claimable: No legal compliance, no legal assurance and no processing of real personal data without Owner GO/GO-DATA.

## Legal notices (disclaimer)

- This portfolio report does not certify legal compliance.
- Preliminary governance classification only — does not replace a conclusive legal assessment.
- The legal assessment may require a specialized legal review.
- No real personal data is processed unless this is explicitly approved.
- Human responsibility remains mandatory; AI does not make automatic decisions about persons.
- This report serves governance and compliance preparation on an evidence basis. It does not constitute legal advice, certification, or a conformity attestation.
